Automatic security configuration
Abstract
A method, a computerized apparatus and a computer program product for automatic generation of security configuration and deployment thereof. The method comprises monitoring programs executed by a device within an organizational network, to identify an attempt to transmit outgoing communications. In response to determining a program executed by the device is attempting to transmit an outgoing communication: checking whether the program is listed in a base list of authorized programs. In response to determining that the program is listed in the base list, adding the program to a list of authorized programs.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method comprising:
monitoring programs executed by a device within an organizational network, to identify an attempt to transmit outgoing communications; in response to determining a program executed by the device is attempting to transmit an outgoing communication:
checking whether the program is listed in a base list of authorized programs;
in response to determining that the program is listed in the base list, adding the program to a list of authorized programs.
2 . The method of claim 1 , wherein prior to checking whether the program is listed in the base list, checking whether the program is listed in the list, wherein said checking whether the program is listed in the base list is performed in response to determining that the program is not listed in the list.
3 . The method of claim 2 , wherein in response to determining that the program is not listed in the list, blocking the outgoing communication, whereby preventing the program from transmitting the outgoing communication.
4 . The method of claim 3 , wherein said blocking is performed prior to said checking whether the program is listed in the base list.
5 . The method of claim 1 , further comprising allowing the program to transmit the outgoing communication.
6 . The method of claim 1 , further comprising:
in response to determining that a second program is attempting to transmit a second outgoing communication:
checking whether the second program is listed in the list;
in response to determining that the second program is not listed in the list:
checking whether the second program is listed in the base list; and
in response to determining that the second program is not listed in the base list, blocking the second outgoing communication, whereby preventing the second program from transmitting the second outgoing communication.
7 . The method of claim 1 , further comprising:
in response to determining that a second program is attempting to transmit a second outgoing communication:
checking whether the second program is listed in the list; and
in response to determining that the second program is listed in the list, allowing the second program to transmit the second outgoing communication, whereby avoiding checking whether the second program is listed in the base list.
8 . The method of claim 1 , further comprising utilizing the list as a whitelist for a security-related tool that is operating within the organizational network.
9 . The method of claim 8 , wherein the security-related tool is a firewall.
10 . The method of claim 8 , wherein said utilizing comprises transmitting the list to the plurality of devices, each of which having the security-related tool installed thereon, wherein the security-related tool is configured to perform selective blocking of communications of programs based on the list.
11 . A computerized apparatus having a processor, the processor being adapted to perform the steps of:
monitoring programs executed by a device within an organizational network, to identify an attempt to transmit outgoing communications; in response to determining a program executed by the device is attempting to transmit an outgoing communication:
checking whether the program is listed in a base list of authorized programs;
in response to determining that the program is listed in the base list, adding the program to a list of authorized programs.
12 . The computerized apparatus of claim 11 , wherein prior to checking whether the program is listed in the base list, checking whether the program is listed in the list, wherein said checking whether the program is listed in the base list is performed in response to determining that the program is not listed in the list.
13 . The computerized apparatus of claim 12 , wherein in response to determining that the program is not listed in the list, blocking the outgoing communication, whereby preventing the program from transmitting the outgoing communication.
14 . The computerized apparatus of claim 13 , wherein said blocking is performed prior to said checking whether the program is listed in the base list.
15 . The computerized apparatus of claim 11 , wherein the processor is further adapted to allow the program to transmit the outgoing communication.
16 . The computerized apparatus of claim 11 , wherein the processor is further adapted to perform the steps of:
in response to determining that a second program is attempting to transmit a second outgoing communication:
checking whether the second program is listed in the list;
in response to determining that the second program is not listed in the list:
checking whether the second program is listed in the base list; and
in response to determining that the second program is not listed in the base list, blocking the second outgoing communication, whereby preventing the second program from transmitting the second outgoing communication.
17 . The computerized apparatus of claim 11 , wherein the processor is further adapted to perform the steps of:
in response to determining that a second program is attempting to transmit a second outgoing communication:
checking whether the second program is listed in the list; and
in response to determining that the second program is listed in the list, allowing the second program to transmit the second outgoing communication, whereby avoiding checking whether the second program is listed in the base list.
18 . The computerized apparatus of claim 11 , wherein the processor is further adapted to utilize the list as a whitelist for a security-related tool that is operating within the organizational network.
19 . The computerized apparatus of claim 18 , wherein said utilizing comprises transmitting the list to the plurality of devices, each of which having the security-related tool installed thereon, wherein the security-related tool is configured to perform selective blocking of communications of programs based on the list.
20 . A computer program product comprising a non-transitory computer readable storage medium retaining program instructions, which program instructions when read by a processor, cause the processor to perform a method comprising:
monitoring programs executed by a device within an organizational network, to identify an attempt to transmit outgoing communications; in response to determining a program executed by the device is attempting to transmit an outgoing communication:
checking whether the program is listed in a base list of authorized programs;
in response to determining that the program is listed in the base list, adding the program to a list of authorized programs.Join the waitlist — get patent alerts
Track US2019089595A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.